
scan2payme Security & Risk Analysis
wordpress.org/plugins/scan2paymePlugin for displaying payment QR-Codes in WooCommerce order pages.
Is scan2payme Safe to Use in 2026?
Generally Safe
Score 100/100scan2payme has no known CVEs and is actively maintained. It's a solid choice for most WordPress installations.
The "scan2payme" plugin, in version 1.0.4, exhibits a mixed security posture. On the positive side, the plugin demonstrates excellent coding practices in several areas. All SQL queries are properly prepared, and all output is correctly escaped, indicating a strong defense against common injection and XSS vulnerabilities. There are no file operations or external HTTP requests, further reducing the attack surface. The absence of bundled libraries is also a good sign, as it avoids potential vulnerabilities from outdated dependencies.
However, a significant concern arises from the attack surface analysis. The plugin has a single entry point through an AJAX handler that completely lacks authentication checks. This presents a critical risk, as any unauthenticated user could potentially interact with this handler, leading to unintended actions or information disclosure. While taint analysis did not reveal any issues, the presence of an unprotected AJAX endpoint bypasses the need for taint to manifest a vulnerability, as the lack of authorization is the primary flaw.
Furthermore, the plugin's vulnerability history is entirely clean, with no recorded CVEs. While this is a positive indicator, it's important to note that a clean history does not guarantee future security. Coupled with the unprotected AJAX endpoint, this suggests that while the developers may have good intentions, there's a critical oversight in securing critical functionalities. The plugin's strengths in preventing common web vulnerabilities are overshadowed by the single, yet significant, vulnerability in its authentication mechanism.
Key Concerns
- AJAX handler without authentication
scan2payme Security Vulnerabilities
scan2payme Code Analysis
Output Escaping
scan2payme Attack Surface
AJAX Handlers 1
WordPress Hooks 4
Maintenance & Trust
scan2payme Maintenance & Trust
Maintenance Signals
Community Trust
scan2payme Alternatives
Checkout Gateway for IRIS
checkout-gateway-iris
Unofficial IRIS checkout payment gateway for WooCommerce. Accept payments via IRIS and manage order statuses efficiently.
Czech QR Payments for WooCommerce
czech-qr-code-bank-transfer-payment-for-woocommerce
Payment method for fast QR code bank transfer payment from Czech banking mobile apps
UPI QR Code Payment Gateway for WooCommerce
upi-qr-code-payment-for-woocommerce
This Plugin enables WooCommerce shop owners to get direct and instant payments through UPI apps like BHIM, GooglePay, PhonePe or any banking UPI app.
Bangladeshi Payment Gateways – Make Payment Using QR Code
bangladeshi-payment-gateways
Bangladeshi Payment Gateways for WooCommerce.
HitPay Payment Gateway for WooCommerce
hitpay-payment-gateway
HitPay Payment Gateway Plugin allows HitPay merchants to accept PayNow QR, Cards, Apple Pay, Google Pay, WeChatPay, AliPay and GrabPay Payments.
scan2payme Developer Profile
1 plugin · 0 total installs
How We Detect scan2payme
Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.
Asset Fingerprints
/wp-content/plugins/scan2payme/js/scan2payme-admin.jsscan2payme/js/scan2payme-admin.js?ver=HTML / DOM Fingerprints
<!-- TODO does the default value work if this is a fresh installation? -->data-nonce="scan2payme-account-nonce"scan2payme_ajax_object/wp-json/scan2payme/v1/options